CVE-2025-15232: Tenda M3 setAdPushInfo formSetAdPushInfo stack-based overflow
A vulnerability was identified in Tenda M3 1.0.0.13(4903). This vulnerability affects the function formSetAdPushInfo of the file /goform/setAdPushInfo. The manipulation of the argument mac/terminal leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15232?
CVE-2025-15232 is classified as a high severity vulnerability due to its potential for remote exploitation leading to stack-based buffer overflow.
How does CVE-2025-15232 affect the Tenda M3 router?
CVE-2025-15232 affects the Tenda M3 router by allowing attackers to manipulate the mac/terminal argument in the formSetAdPushInfo function, leading to a stack-based buffer overflow.
What is the attack vector for CVE-2025-15232?
The attack vector for CVE-2025-15232 is remote, enabling attackers to exploit the vulnerability from outside the network.
How do I fix CVE-2025-15232?
To fix CVE-2025-15232, update the Tenda M3 router to the latest firmware version that addresses this vulnerability.
Are there any mitigations for CVE-2025-15232?
Mitigations for CVE-2025-15232 include disabling remote access to the router and only accessing it over a secure, internal network.